ci: resolve package install sha from a flake input - #2327
Merged
Conversation
Workflows that install nix packages from github:supabase/postgres/<sha> hardcode the run's own commit sha, which breaks when the same workflow runs in a repo whose flake re-exports this one. Adds resolve-git-sha, which falls back to the flake input pinned in flake.lock when a repo variable names one, else uses github.sha unchanged.
imor
approved these changes
Jul 31, 2026
Collaborator
|
How in the world did this PR break my branch/PR...https://github.com/supabase/postgres/actions/runs/30667526580/job/91279509777?pr=2326 |
Collaborator
|
ugghhh its because testinfra workflow has |
hunleyd
added a commit
that referenced
this pull request
Aug 8, 2026
…c-spool-path-defaults-onto-the-10gb-root-volume * origin/develop: (26 commits) Lots of bootstrap script clean ups (#2326) ci: Fix nix-build PUSH_TO_CACHE (#2345) ci/nix-install-ephemeral: Drop sticky disk config (#2346) chore: bump postgres_release to cut fresh AMIs (includes #2334) (#2349) fix(multigres): stop base config data_directory from overriding pooler data dir (#2344) fix(cron): remove unnecessary TRIGGER grant on cron.job_run_details from postgres (#2334) chore: enable extension version restriction (warn) and cut AMIs (#2315) feat(nix): add site-env packages for rolling instance updates (#2283) ci: resolve package install sha from a flake input override (#2327) fix(multigres): remove dangling wal-g include from postgresql.conf (#2338) fix: Allow test CI pipelines to use old Int CA access. For staging only (#2330) chore(nix): remove maintainers field from package definitions (#2280) chore: bump multigres to b713432 (#2323) ci: Use arm-native-runner for kvm builds on aarch64-linux (#2319) Whole lot of ansible clean up (#2272) fix(ansible): drop no-op zpool loop item from zswap task (#2322) ci: Fix dockerhub-release-matrix matrix generation (#2320) chore: bump pgctld (#2318) fix(ansible): skip zswap params the kernel does not expose (#2321) feat(docker): add Dockerfile-supabase base image and rewrite Dockerfile-multigres as layered image (#2160) ...
hunleyd
added a commit
that referenced
this pull request
Aug 8, 2026
…nix-pkg-for-pgbackrest * origin/develop: (36 commits) Lots of bootstrap script clean ups (#2326) ci: Fix nix-build PUSH_TO_CACHE (#2345) ci/nix-install-ephemeral: Drop sticky disk config (#2346) chore: bump postgres_release to cut fresh AMIs (includes #2334) (#2349) fix(multigres): stop base config data_directory from overriding pooler data dir (#2344) fix(cron): remove unnecessary TRIGGER grant on cron.job_run_details from postgres (#2334) chore: enable extension version restriction (warn) and cut AMIs (#2315) feat(nix): add site-env packages for rolling instance updates (#2283) ci: resolve package install sha from a flake input override (#2327) fix(multigres): remove dangling wal-g include from postgresql.conf (#2338) fix: Allow test CI pipelines to use old Int CA access. For staging only (#2330) chore(nix): remove maintainers field from package definitions (#2280) chore: bump multigres to b713432 (#2323) ci: Use arm-native-runner for kvm builds on aarch64-linux (#2319) Whole lot of ansible clean up (#2272) fix(ansible): drop no-op zpool loop item from zswap task (#2322) ci: Fix dockerhub-release-matrix matrix generation (#2320) chore: bump pgctld (#2318) fix(ansible): skip zswap params the kernel does not expose (#2321) feat(docker): add Dockerfile-supabase base image and rewrite Dockerfile-multigres as layered image (#2160) ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Workflows that install nix packages via
github:supabase/postgres/<sha>#pkguse the run's own commit sha. That breaks when the exact same workflow file runs in a different repo.Adds a
resolve-git-shacomposite action: if aGIT_SHA_FROM_FLAKE_INPUTrepo variable names a flake input, resolves that input's pinned rev fromflake.lock; otherwise falls back togithub.shaunchanged. Wired into the four workflows that construct these install refs (ami-release-nix.yml,testinfra-ami-build.yml,qemu-image-build.yml,test.yml).build-ami/action.ymlgets a second input,packages_git_sha, kept separate fromgit_sha(AMI identity tag, used for cache lookups, must stay the triggering commit) so the two don't get conflated.No effect here: the variable is never set in this repo, so every site falls through to
github.shaexactly as today.